DocumentCode :
2274024
Title :
Visualizing enterprise-wide security (VIEWS)
Author :
Brennan, J.J. ; Faatz, Don ; Rudell, Mindy ; Zimmerman, Carson
Author_Institution :
Mitre Corp., USA
fYear :
2004
fDate :
6-10 Dec. 2004
Firstpage :
71
Lastpage :
79
Abstract :
This paper discusses VIEWS, a specification for building diagrams that describe the security features of systems. The authors´ recent experience with providing security architecture and engineering support to organizations with large, distributed applications suggests that security architecture and assurance efforts could benefit by following other engineering disciplines, where using graphical models is the norm. Security diagrams can help security architects understand a system ´s security posture and can assist them in detecting vulnerabilities. Additionally, diagrams facilitate communications about the security features of a design. The output of a modeling effort using VIEWS is a diagram depicting a system´s security features as well as those of the environment in which the system operates. A goal of VIEWS is to allow the display of important security features without injecting cluttering detail. This paper presents examples of security diagrams built with VIEWS.
Keywords :
data visualisation; distributed processing; formal specification; organisational aspects; security of data; graphical models; security diagrams; visualizing enterprise-wide security; Buildings; Communication system security; Computer security; Data security; Design engineering; Displays; Graphical models; Information security; Technology transfer; Visualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2004. 20th Annual
ISSN :
1063-9527
Print_ISBN :
0-7695-2252-1
Type :
conf
DOI :
10.1109/CSAC.2004.49
Filename :
1377217
Link To Document :
بازگشت